I have one field value as a datetime field, and I want the data of only the latest time. How can I write this query?
My current search is:
index="ad_dns_new" sourcetype="resolve_json"|eval k=strptime(DateTime,"%Y-%m-%dT%H:%M:%S")|eval New_Date=strftime(k,"%d-%m-%Y %H:%M:%S") | table HealthCheck,Result,New_Date,Customer|chart values(Result) as Result over HealthCheck by New_Date
I am attaching an image of my current output. From that, I want data of 11th nov 15:36:57.
How can I do that?
I look forward to hearing from you.
... View more